CVE-2026-53822

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

16 Jun 2026, 02:52

Type Values Removed Values Added
First Time Openclaw
Openclaw openclaw
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-2j8v-hwgc-x698 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-2j8v-hwgc-x698 - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-command-argument-modification-via-shell-wrapper-between-approval-and-execution - () https://www.vulncheck.com/advisories/openclaw-command-argument-modification-via-shell-wrapper-between-approval-and-execution - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
CWE CWE-77

12 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 22:16

Updated : 2026-06-16 02:52


NVD link : CVE-2026-53822

Mitre link : CVE-2026-53822

CVE.ORG link : CVE-2026-53822


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')